Capability matrix
The capability matrix defines explicit permissions across Rival Enterprise. It details which platform actions each role can perform directly, which actions require administrative approval, and which actions are restricted.
✅ = full access · ❌ = restricted · — = not applicable for that role.
Role definitions summary
Section titled “Role definitions summary”- Standard Rival User — self-serve individual account operating outside an enterprise workspace boundary.
- Enterprise Admin — IT and operations administrators with global governance and workspace management authority.
- Enterprise Team Member — enterprise employees building and executing automations within pre-established company guardrails.
For the narrative description of each role, see Roles overview.
Workspace administration and governance
Section titled “Workspace administration and governance”| Feature / action | Standard User | Enterprise Admin | Enterprise Team Member |
|---|---|---|---|
| Manage workspace settings | Full (personal) | Full (org-wide) | View only |
| Manage SSO and identity sync | — | ✅ | ❌ |
| Configure global guardrails | — | ✅ | ❌ |
| Manage users and invitations | — | ✅ | ❌ |
| Create and manage teams | — | ✅ | View assigned |
| Manage billing and run balance | — | Org-wide control | View assigned balance |
| View audit logs | — | Global visibility | Team-scoped |
See Account settings, SSO setup, Guardrails and allowed models, and Audit logs.
Tool engineering and development
Section titled “Tool engineering and development”| Feature / action | Standard User | Enterprise Admin | Enterprise Team Member |
|---|---|---|---|
| Build tools via RivalBot | ✅ | ✅ | Guided / governed |
| Write custom code handlers | ✅ | ✅ | Role permitted |
| Attach workspace secrets | Personal secrets | Org-wide secrets | Admin approved only |
| Run interactive tests | ✅ | ✅ | ✅ |
| Publish to org marketplace | — | Direct (org-wide) | Requires admin approval |
| Deprecate published tools | Personal assets | Org-wide assets | Assigned assets only |
Secret handling is covered in Secrets.
Connector and data governance
Section titled “Connector and data governance”| Feature / action | Standard User | Enterprise Admin | Enterprise Team Member |
|---|---|---|---|
| Set up enterprise connectors | — | Org-level setup | ❌ |
| Assign connector access | — | ✅ | ❌ |
| Use approved connectors | Personal only | ✅ | Assigned / approved only |
| Request new system connections | — | Direct addition | In-app request |
See Connector governance and security.
Workflows and agent execution
Section titled “Workflows and agent execution”| Feature / action | Standard User | Enterprise Admin | Enterprise Team Member |
|---|---|---|---|
| Execute approved agents | ✅ | ✅ | ✅ |
| Run multi-step workflows | ✅ | ✅ | ✅ |
| Sign off on pending approvals | — | ✅ | Designated lead only |
| Override execution guardrails | ✅ | ✅ | ❌ |
See Approval workflows.
Key capability takeaways
Section titled “Key capability takeaways”- Self-serve vs. enterprise — Standard Users operate with full personal freedom over their own workspace, while Enterprise Team Members operate inside curated, admin-managed catalogs.
- Publishing controls — Enterprise Team Members can construct tools and workflows freely, but publishing them to the shared organization catalog requires explicit Enterprise Admin review.
- Connector boundaries — system connections are established centrally by administrators, ensuring credentials remain encrypted and isolated from end users.
Next steps
Section titled “Next steps”- Review full role descriptions → Roles overview
- See how product interface views adapt per role → Navigation by role
- Configure workspace governance baselines → Account settings